Time |
Victim OS |
Infection Source |
C&C Server |
DNS Lookups & Failed Connects |
Infection Port |
Packet Trace |
Detection Signatures |
Infection Chatter |
BotHunter Analysis |
Behavioral Cluster |
Forensic Logs |
Antivirus Labels |
Packed Malware_Binary |
Unpacked egg.exe |
Unpacked egg.asm |
Packer PEID |
Data Strings |
Syscall Trace |
T:00:08:00 | Win2K-f | 98.191.61.77 (COX.NET): COX COMMUNICATIONS, LAFAYETTE, LOUISIANA, US. (DSL) |
n/a | EE:www.starman.ee FI:www.if.ee :phonewire.dd.blueline.be :phonelogin.dd.blueline.be JP:ufospace.etowns.net KR:theforums.bbsindex.com LT:phonewire.dnip.net GB:phonelogin.dnip.net US:microsoft.com :cx10man.weedns.com :fx010413.whyI.org |
135 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
01:00:00 | Win2K-f | 110.77.236.184 (-): CAT TELECOM PUBLIC COMPANY LTD CAT, TH. (DSL) |
n/a | :www.google.com :iseovcoa.info :pfnohzqj.com :gaskudwk.net :ajrddbqpgd.org :igiroj.org :zkmxitewsp.net US:ksysnnxu.biz :xlrxicuwlw.com :utmqqzv.info :cxgfqkanq.info :txcqo.info :havsibczpkt.com :wpwmdwzhjfq.com US:zclbunzbe.biz :vabrxkqc.com :vnhzwut.com :mhunqjgu.org :cfxidwcl.info :titvrxjc.info :zezmswbxe.info US:rdymml.biz :vudldfdaxk.com :xclyhu.com :ltumkama.info :jnydobsnzd.info :dsbqxgijcyg.org :sdkubhqw.info US:jmwbyc.biz :ybhnbiuel.org :lrbnmh.info :tkrpvnw.net :qoxcvynv.com :jnqwhygmxo.org :qxjenki.com :jsszfqf.com :isnarvafq.net :anchomei.info US:lmkavgytrs.biz :ahkfzqkr.net :sfongv.info US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:01:05:00 | WinXP | 37.150.35.99 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
T:01:45:00 | WinXP | 37.150.35.99 (-): . |
213.155.14.161:80 | DE:citi-bank.ru :albat.somee.com **:boemaclasic.ro TH:www2.bpp.go.th :caetanojrecruz.adv.br DE:buyukfirsat.bu.funpic.org GB:www.bsnlondon.co.uk GR:dincermakinasanayi.com.tr |
445 | pcap | raw alerts ruleset |
http 2 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 94227c2434 NEW |
none[none] | none:none |
none|none | none | none |
03:30:00 | Win2K-f | 185.9.157.217 (-): . |
n/a | :www.maxmind.com :getmyip.co.uk :www.getmyip.org US:checkip.dyndns.org DE:131.220.6.26:80 EU:91.198.22.70:80 |
445 | pcap | raw alerts ruleset |
http 4 lines |
Yeah : 0.8 profile |
none | summary tarball |
2 of 37 | 223d8089f8 NEW |
none[3] | none:none |
StarForce| | none | trace |
T:06:51:00 | WinXP | 78.8.132.255 (NET.PL): DYNAMIC BROADBAND SERVICES, WROCLAW, DOLNOSLASKIE, PL. (DIAL) |
n/a | 445 | pcap | raw alerts ruleset |
shell ftp 15 lines |
Yeah : 1.3 profile |
none | summary tarball |
none | 038c63c8d5 NEW |
none[none] | none:none |
none|none | none | none | |
07:10:00 | Win2K-f | 193.34.109.150 (MCCNET.RO): S.C. MCC EURO GRUP S.R.L, BUCHAREST, BUCURESTI, RO. (DSL) |
n/a | US:www.w3.org :vncptgq.org :enmngdwvm.org US:ehtyef.biz :demauamw.net :uwwpmk.org US:mphfywot.biz :pdmdxcgnf.net :vbbmzhr.com :baapzu.info :dmvblxkxzog.info :kqhhhipjyvq.info :astowx.com :jokadz.org :orjptvw.net :nepsrlggntw.info :esbyy.com :gqueivszi.net US:calpdhd.biz :deboii.net US:zehowdw.biz :eryrz.net :rhnwiuqvboz.org :cunvqrho.net US:kjuel.biz :nzdllgdc.org :dslidenzret.org :tlobdd.com :obvqchqr.org US:bdnbmbrzfi.biz :cmbsobhth.org :gbqxgicr.com US:ynfxoydk.biz :vmxcgtuly.com :ffrxmjzm.com :grrifwfjcdp.net :gthexbcczh.info :inooboq.info :lcnjmrhb.org :pfnohzqj.com US:ywgwthj.biz :bfosusagnv.com :xlrxicuwlw.com US:wiircwnyi.biz :zxwkdrk.info :dgklsbpiuu.com :mhunqjgu.org :bbqjul.info :poqwtiws.com :cwmbyouz.org :athvwvdsqj.com :fbkuwxuqu.com US:qtkfitlen.biz :cwkrq.org :lknlfyjs.com :anchomei.info :uotavuba.com US:kbwwkesw.biz US:lrohcf.biz :qdnsui.org US:lpoeegz.biz US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 17 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:08:23:00 | WinXP | 93.157.157.142 (HISPEED.PL): USLUGI INTERNETOWE MAJESTIC, PL. (DSL) |
n/a | DE:citi-bank.ru CA:jewellerybazaar.net BR:casaebar.com.br :canossadhule.in :cansesiasknefesi.com DE:how2gethazanat.ho.funpic.de :www.evishop.de :chihuahuaupinghome.com IN:dehaspas.com TR:devdijital.com US:sobrenaturalbr.net BR:direitopublico.com.br DE:213.155.14.161:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 0.8 profile |
none | summary tarball |
37 of 43 | ca3e3b13f3 NEW |
none[none] | none:none |
none|none | none | none |
10:15:00 | Win2K-f | 89.146.184.103 (NET.BA): BRAS PPPOE POOL UPGRADE, SARAJEVO, FEDERATION OF BOSNIA AND HERZEGOVINA, BA. (DSL) |
n/a | US:www.ask.com :havsibczpkt.com :qoxcvynv.com :ukbdq.net :xavepuxgh.com :vismubsya.info :twluponqol.com :tlobdd.com :gvbzzgry.net US:zclbunzbe.biz :tqgcsy.net :dilarfg.info :fpmswehd.info :omhdutrnqrg.org :vmxcgtuly.com :pdmdxcgnf.net :ybhnbiuel.org :plsqjsp.org :bpgfldszte.org :cfxidwcl.info :gmrnuirpocz.net :gthexbcczh.info US:duevkk.biz :xlrxicuwlw.com :titvrxjc.info :oyclffbv.com US:ofcjokby.biz :vncptgq.org :lvpthxyoh.net :jnqwhygmxo.org :tmctv.com US:ktmzd.biz :astowx.com :vudldfdaxk.com :iyfhgdmraxo.info :hhlde.org :kcvbtvlds.org :mzqnsxur.com :nzdllgdc.org :mzayj.com :pvjngkjz.com :sdkubhqw.info US:zjtncvnuez.biz :eyrnknyyi.com :nepsrlggntw.info :esbyy.com :lfrerzwytr.com :cwmbyouz.org :cunvqrho.net :feqmeszk.org :wadmfon.org :aqfzimakxo.org :oyvzszbv.org :bbqjul.info :wvubjxd.info :suycrcwefg.net US:tjsjlqzpeux.biz US:nwyfvijb.biz :dslidenzret.org :quhtukfp.info :lrbnmh.info US:149.20.56.32:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:11:46:00 | WinXP | 37.229.236.47 (-): . |
n/a | DE:citi-bank.ru :cikmayedekparca.com :brucegarrod.com :cbbasimevi.com :brandaoematos.com.br **:caglarteknik.com :bharatisangli.in BR:cacs.org.br RO:butacm.go.ro EU:boyabateml.k12.tr :casbygroup.com |
445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
38 of 42 | 8a2553433c NEW |
none[none] | none:none |
none|none | none | none |
12:02:00 | Win2K-f | 85.152.233.184 (CM-85-152-234-10.TELECABLE.ES): TELECABLE, OVIEDO, ASTURIAS, ES. (DSL) |
n/a | :www.maxmind.com DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
13:15:00 | Win2K-f | 94.153.18.236 (KYIVSTAR.NET): UA-KYIVSTAR, KIEV, KYYIV, UA. (DSL) |
n/a | :www.maxmind.com :www.getmyip.org EU:checkip.dyndns.org DE:131.220.6.26:80 US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 3 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:13:45:00 | Win2K-f | 24.231.70.34 (PERSONA.CA): PERSONA COMMUNICATIONS, HALIFAX, NOVA SCOTIA, CA. (DSL) |
n/a | FI:www.if.ee EE:www.starman.ee :telephone.dd.blueline.be :phonelogin.dd.blueline.be KR:koopa.dnip.net US:fx010413.whyI.org |
139 | pcap | raw alerts ruleset |
other 0 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
16:55:00 | Win2K-f | 5.53.198.165 (-): . |
n/a | :www.google.com :dwomyc.info US:eobcmov.biz :zoxoughk.net :uhbcvpx.org :usgzmvz.info :aqqdjaiv.com :wyzebnehgna.org :gmyvquuxvvx.net :ifnvuumwf.info US:vbnmfobr.biz :lzuigmldv.info :qrxywbeo.net :janadsoswgg.com :qstrv.net US:ytoupasu.biz :wjwao.net :twgtcpq.org :xibntqrtu.org :bgxnznrufh.net US:ntlmugr.biz :rmvhgahdej.net :ckmifuw.info :hokfxuyklg.net US:almtrucy.biz US:erjzxgkz.biz :addbpzm.net :hwhcrzdpkj.info :pndmgkngehn.org :whvwcieg.org :dlaee.net US:204.152.184.139:80 74.125.224.144:80 |
445 | pcap | raw alerts ruleset |
http 2 lines |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |
T:19:09:00 | WinXP | 121.91.194.18 (ISEEK.COM.AU): ISEEK COMMUNICATIONS, SYDNEY, NEW SOUTH WALES, AU. (DSL) |
n/a | DE:citi-bank.ru | 445 | pcap | raw alerts ruleset |
http 1 line |
Yeah : 1.3 profile |
none | summary tarball |
41 of 42 | 22340630ac NEW |
none[none] | none:none |
none|none | none | none |
23:06:00 | Win2K-f | 120.29.102.203 (-): . |
n/a | US:www.ask.com :qstrv.net :klydfbtoswg.org :tnimtav.org :zigbwwmnj.org :uwlbk.info :xwmkgslnxpa.net :uodskueipzg.com :vxvzfdt.org :qduguxbxld.net :jvtlpc.org :jhextbt.org :yzetdwhqct.net :hyrtckie.com US:eobcmov.biz :bhzojkp.org US:ognsyqxeva.biz US:slsex.com :okbwkf.info US:nlbmiytm.biz :vemgwwcomos.com :xfnrhex.com :dijswm.org :usgzmvz.info US:fwgnbtylowy.biz :ilvlkbat.info :ipqiqdtzl.net :xzwqxfar.net :yjhlbnnv.org US:hwivkwxz.biz :cgrzhbqj.com :chknt.org :pwwqossnmf.info :yadhrd.net :addbpzm.net :aomcpwy.net :imllnjv.info :xzzrirvom.info :gezfuxsvvz.com US:zoapidx.biz :fvcvucsf.com :kopblpfv.info :cjbsyyhrm.info US:efwqken.biz :hwhcrzdpkj.info :jrsbnxaen.com US:oemjznv.biz :kexawtn.org :fietbpo.info :sgxct.com :imzbihuvnf.com :ofibkyjzlp.net :tywjwvxvx.info :gbpphrbasm.info :pevrjib.com US:dpijevzc.biz :xtonvwgl.com :yctwqq.org :khxstokfyuk.org :xtouuxhrrq.com :xocoqyb.net US:204.152.184.139:80 |
445 | pcap | raw alerts ruleset |
http 1 line |
Argh : 0.3 profile |
none | summary tarball |
none | none | none | none | none | none | none |